mirror of https://github.com/status-im/consul.git
72 lines
3.8 KiB
Plaintext
72 lines
3.8 KiB
Plaintext
|
{
|
||
|
"name": "envoy.filters.network.rbac",
|
||
|
"config": {
|
||
|
"rules": {
|
||
|
"action": "DENY",
|
||
|
"policies": {
|
||
|
"consul-intentions": {
|
||
|
"permissions": [
|
||
|
{
|
||
|
"any": true
|
||
|
}
|
||
|
],
|
||
|
"principals": [
|
||
|
{
|
||
|
"authenticated": {
|
||
|
"principal_name": {
|
||
|
"safe_regex": {
|
||
|
"google_re2": {
|
||
|
},
|
||
|
"regex": "^spiffe://[^/]+/ns/default/dc/[^/]+/svc/web$"
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
},
|
||
|
{
|
||
|
"authenticated": {
|
||
|
"principal_name": {
|
||
|
"safe_regex": {
|
||
|
"google_re2": {
|
||
|
},
|
||
|
"regex": "^spiffe://[^/]+/ns/default/dc/[^/]+/svc/cron$"
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
},
|
||
|
{
|
||
|
"and_ids": {
|
||
|
"ids": [
|
||
|
{
|
||
|
"authenticated": {
|
||
|
"principal_name": {
|
||
|
"safe_regex": {
|
||
|
"google_re2": {
|
||
|
},
|
||
|
"regex": "^spiffe://[^/]+/ns/default/dc/[^/]+/svc/[^/]+$"
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
},
|
||
|
{
|
||
|
"not_id": {
|
||
|
"authenticated": {
|
||
|
"principal_name": {
|
||
|
"safe_regex": {
|
||
|
"google_re2": {
|
||
|
},
|
||
|
"regex": "^spiffe://[^/]+/ns/default/dc/[^/]+/svc/unsafe$"
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|
||
|
},
|
||
|
"stat_prefix": "connect_authz"
|
||
|
}
|
||
|
}
|